THREAT OPS › Threat News › [GHSA] GHSA-998g-7v5w-cr7g (medium) — MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
[GHSA] GHSA-998g-7v5w-cr7g (medium) — MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
GHSA-998g-7v5w-cr7g Severity: medium CVE: CVE-2026-63642
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
# Vulnerability — Blind SSRF via `CHECK_ARTICLE_URL` (MagicMirror² newsfeed)
> Analysis of the PoC `exploit-ssrf-newsfeed.js`. > Target: `newsfeed/node_helper.js` of MagicMirror², socket.io namespace `/newsfeed`.
---
## Identification
| Field | Value |
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-63642cve
- https://target/url
- https://webhook.siteurl
- socket.iodomain
Original source: https://github.com/advisories/GHSA-998g-7v5w-cr7g